Security Monitoring Detection Engineer (R-00143)

 Posted a month ago
     
2-5 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The role involves applying software engineering principles to security rules through 'Detection as Code' and mapping strategies against the MITRE ATT&CK framework. Additionally, the engineer will analyze telemetry data, tune detection rules for optimization, and manage the full detection lifecycle.

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

\n


Job Responsibilities
 
  • "Detection as Code" (DaC): Applying software engineering principles (version control, CI/CD, testing) to security rules.
  • Threat Mapping: Mapping detection strategies against frameworks such as MITRE ATT&CK to identify coverage gaps.
  • Log Analysis: Analyzing telemetry from endpoint, network, cloud, and identity systems to identify anomalous patterns.
  • Tuning and Optimization: Continuously tuning rules to reduce noise and enhance actionable alerts.
  • Detection Lifecycle Management: Designing, developing, testing, deploying, and maintaining rules to detect threats.


Job Qualifications
 
  • Technical Expertise: Strong proficiency in Python scripting, SQL, and regex, as well as experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel).
  • Behavioral Analysis: Understanding of attacker techniques, tactics, and procedures (TTPs).
  • Data Analysis: Ability to parse and analyze large-scale log data for anomalies.
  • Background: Often requires experience in SOC analysis, incident response, or threat hunting.


\n

We’re actively searching for talented and expereinced professionals who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:

 

- Competitive salary, paid twice per month

- Best in class medical coverage

- 100% of medical premiums covered by True Zero

- Company wide new business incentive programs

- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)

- 3 weeks of PTO starting + 11 Paid Holidays Annually

- 401k Program with 100% company match on the first 4%

- Monthly reimbursement of Cell Phone and Home Internet costs

- Paternity/Maternity Leave

- Investment in training and certifications to broaden and deepen your technical skills

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Detection Engineer

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified